1

Weekend Governance Risk Compliance Jobs in Massachusetts

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...

The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...

IT Risk & Compliance Analyst

Andover, MA · Remote

$95K - $95K/yr

Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...

next page

Showing results 1-20

Weekend Governance Risk Compliance information

What is a weekend Governance Risk Compliance role?

A Weekend Governance Risk Compliance (GRC) professional is responsible for overseeing and managing an organization’s risk management, compliance, and governance programs during weekend hours. This role typically involves monitoring regulatory compliance, conducting risk assessments, and ensuring that internal controls are maintained outside of regular business hours. Weekend GRC professionals help organizations maintain continuous security and compliance coverage, address urgent risk issues that arise, and support incident response efforts when needed. Their work is crucial for industries that require 24/7 compliance and risk oversight.

How does working a weekend Governance Risk Compliance role differ from standard weekday positions in terms of responsibilities and team collaboration?

In a weekend GRC position, you will often be responsible for monitoring compliance activities that require coverage outside of typical business hours, such as responding to urgent risk events or ensuring ongoing regulatory adherence. While some tasks may be more independent, you’ll still collaborate closely with weekday teams through detailed handover reports, virtual meetings, and shared documentation. This structure allows for continuous oversight and can present unique challenges, such as quickly adapting to issues without immediate in-person support. However, it also offers the opportunity to develop strong problem-solving skills and gain visibility with leadership by managing critical incidents during off-hours.

What are the key skills and qualifications needed to thrive as a weekend Governance Risk Compliance professional?

To thrive as a Weekend Governance Risk Compliance professional, you need a strong understanding of risk management frameworks, regulatory requirements, and compliance standards, often supported by a relevant degree or certifications like CISA, CRISC, or CISSP. Familiarity with GRC tools (such as RSA Archer or ServiceNow), audit software, and documentation systems is typically required. Attention to detail, analytical thinking, and effective communication are essential soft skills for identifying risks and collaborating with stakeholders. These skills are crucial for ensuring organizations remain compliant, minimize risks, and maintain operational integrity during off-peak hours.

What is the difference between Weekend Governance Risk Compliance vs Weekend Compliance Officer?

AspectWeekend Governance Risk ComplianceWeekend Compliance Officer
CertificationsGRC certifications, ISO standardsCompliance certifications, industry-specific licenses
Work EnvironmentCorporate offices, financial institutionsRetail, manufacturing, or service settings
Job FocusRisk management, policy enforcement, governanceMonitoring compliance, audits, reporting

Weekend Governance Risk Compliance professionals focus on managing organizational risks and governance policies, often working in corporate or financial sectors. Weekend Compliance Officers primarily ensure adherence to industry regulations in various operational environments. Both roles require compliance knowledge but differ in scope and focus, with GRC roles emphasizing risk and governance frameworks.

What are the most commonly searched types of Governance Risk Compliance jobs in Massachusetts?

The most popular types of Governance Risk Compliance jobs in Massachusetts are:

What cities in Massachusetts are hiring for Weekend Governance Risk Compliance jobs?

Cities in Massachusetts with the most Weekend Governance Risk Compliance job openings:

Principal Security Governance, Risk & Compliance Analyst

CarGurus

Boston, MA • On-site

Full-time

Posted 11 days ago


Job description

Role overview

The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.

The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.

What you'll do

  • Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.

What you'll bring

  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs.
  • Experience supporting SOX ITGCs in partnership with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills with the ability to influence technical and business stakeholders.